| |
|
|
|
cURL Mailing List Monthly Index Single Mail
curl-library Mailing List Archives
FLAW: curl reveals proxy authentication
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Sun, 3 Aug 2003 01:26:36 +0200 (CEST)
Hi
curl 7.10.6 and all earlier versions have a pretty signification flaw that
When proxy authentication is used in a CONNECT request (as used for all SSL
The name and password can then be captured by an evil host and possibly get
Fix:
Work-arounds:
Ok, the hour is late now and it is weekend. I'll be releasing another curl
If you have any questions about this flaw or patch, you know where to post
-- Daniel Stenberg -- curl: been grokking URLs since 1998 ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01Received on 2003-08-03 These mail archives are generated by hypermail. |
Page updated October 16, 2006.
web site info